peter bassill · operator
$ cve CVE-2020-0601 JSON

CVE-2020-0601 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 89.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS89.44% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-295
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2020-01-14
Last modified2026-06-17

CISA KEV

NameMicrosoft Windows CryptoAPI Spoofing Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productMicrosoft / Windows
Ransomware usenone reported

Affected (14)

VendorProduct
golanggo
microsoftwindows
microsoftwindows 10 1507
microsoftwindows 10 1607
microsoftwindows 10 1709
microsoftwindows 10 1803
microsoftwindows 10 1809
microsoftwindows 10 1903
microsoftwindows 10 1909
microsoftwindows server 1803
microsoftwindows server 1903
microsoftwindows server 1909
microsoftwindows server 2016
microsoftwindows server 2019

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD